CWE-319
898 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding.
This issue affects PanCafe Pro: from < 3.3.2 through 23092025. |
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be displayed on the web page. This information could be exploited by an attacker for other attacks....Show more |
1Moxa 35Uc 1222a Firmware Uc 2222a T Ap FirmwareUc 2222a T Eu Firmware+32 moreJun 17, 2026 Feb 5, 2026 7.0 HIGH· v4 6.8 MEDIUM· v3 N/A· v2 A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitati...Show more |
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material. |
The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A third party with permissions to both call th...Show more |
1Teamviewer 1Digital Employee Experience Jun 17, 2026 Jan 29, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause normally encrypted UDP traff...Show more |
1Dell 2Elastic Cloud Storage ObjectscaleJun 17, 2026 Jan 23, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability in the Fabric Syslog. An unauthenticated attacker with...Show more |
1Dell 2Elastic Cloud Storage ObjectscaleJun 17, 2026 Jan 23, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could p...Show more |
Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Open WebUI. Authe...Show more |
The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-middle or passive inspec...Show more |
1Lenovo 4Thinkplus Fu100 Firmware Thinkplus Fu200 FirmwareThinkplus Tsd303 Firmware+1 moreJun 17, 2026 Jan 14, 2026 6.8 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information. |
Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier. |
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administra...Show more |
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup thro...Show more |
1Iwt 1Facesentry Access Control System Firmware Jun 17, 2026 Jan 8, 2026 9.1 CRITICAL· v4 5.9 MEDIUM· v3 N/A· v2 FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP...Show more |
An attacker with a network connection could detect credentials in clear text. |
iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can e...Show more |
QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers...Show more |
Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext. |
DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information |